Choose an integration
Both run the same server code and return the same signed artifacts.
Tools at a glance
Inputs, outputs and error codes are in the tool reference.
How it fits together
The server is an adapter and a policy boundary, not a source of truth. Every round tool returns the signed attestation plus ready-made verifier arguments for each chain you ask for. Treat that attestation, not the agent’s summary of it, as the trust anchor.Safety model
- Every round spends. There is no idempotency key: a repeated call after an unclear error is a new round. Read state (
describe_feed,get_x402_status) before retrying. - Limits live outside the prompt. On the hosted server, set a spending policy on your wallet. On a local server, use the dry-run lock and caps, which an agent cannot switch off from a conversation.
- Untrusted payment terms are checked. Before anything is signed, the server checks a gateway’s
402terms against what it derives itself: the protocol treasury as payee, the protocol USDC mint, the protocol price and the cluster. - Verify before acting.
build_verifier_calldatabuilds arguments only. Your contract or service callsverify().